Legal

Data processing agreement

Last updated: 5 July 2026

This is a translation of the Dutch original. In case of any discrepancy, the Dutch version prevails.

This data processing agreement (verwerkersovereenkomst) belongs to and forms part of the agreement between the parties ("Main Agreement") and governs the processing of personal data in accordance with article 28 GDPR (AVG).

Parties

  • The Client, as further identified in the associated Main Agreement — hereinafter: Controller (Verwerkingsverantwoordelijke);
  • Procesbrein, registered with the Dutch Chamber of Commerce (Kamer van Koophandel, KvK) under number 42091045, trading under the name Procesbrein (procesbrein.nl) — hereinafter: Processor (Verwerker).

Article 1 — Purpose and scope

1.1 Processor processes personal data solely for the purpose of performing the Main Agreement (the Scan, the Build (Uitvoering) and/or Care (Beheer)) and solely on the basis of written, documented instructions from Controller.

1.2 Processor does not process the data for its own purposes and does not provide it to third parties, except as governed here or as required by law.

1.3 The subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.

Article 2 — Instructions

2.1 Processor processes personal data only on the instructions of Controller, unless a statutory obligation provides otherwise; in that case Processor notifies this in advance, unless that law prohibits it.

2.2 Processor informs Controller if, in its opinion, an instruction infringes the GDPR (AVG) or other privacy legislation.

Article 3 — Confidentiality

3.1 Processor binds persons who have access to the personal data to confidentiality.

3.2 Access is limited to persons for whom this is necessary for the performance of the Main Agreement.

Article 4 — Security

4.1 Processor takes appropriate technical and organisational measures in accordance with article 32 GDPR (AVG). The measures are set out in Annex 2.

4.2 Access to Controller's systems is read-only and is used solely for the agreed analysis.

Article 5 — Sub-processors

5.1 Controller gives Processor general authorisation to engage the sub-processors listed in Annex 3.

5.2 Processor imposes on these sub-processors the same obligations as those set out in this Data Processing Agreement.

5.3 Processor informs Controller in advance of intended changes to the sub-processors, so that Controller can object.

5.4 Processor remains fully liable to Controller for compliance by sub-processors.

Article 6 — Assistance to Controller

6.1 Processor provides reasonable cooperation with requests from data subjects (access, rectification, erasure, restriction, objection, data portability) and forwards requests it receives directly to Controller.

6.2 Processor provides reasonable assistance with a data protection impact assessment (DPIA) and with prior consultation of the supervisory authority.

Article 7 — Data breaches

7.1 Processor informs Controller without undue delay, and at the latest within 48 hours of discovery, of a personal data breach.

7.2 The notification contains at least the nature of the breach, the data and categories concerned, the likely consequences and the measures taken or proposed.

7.3 Notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and/or data subjects remains the responsibility of Controller.

Article 8 — Transfers outside the EEA

8.1 Transfers of personal data outside the European Economic Area take place only with appropriate safeguards, such as the European Commission's standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.

8.2 For the AI processing, a standard log retention of no more than 7 days for abuse detection applies at the sub-processor concerned; input and output are not used for model training.

Article 9 — Return and deletion

9.1 After termination of the Main Agreement, Processor deletes or returns, at Controller's option, all personal data, and deletes existing copies, unless retention is required by law.

9.2 Processor confirms the deletion in writing upon request.

Article 10 — Audit

10.1 Upon request, Processor makes available the information needed to demonstrate compliance with article 28 GDPR (AVG).

10.2 Controller may, at most once a year and with reasonable notice, carry out (or have carried out) an audit. The reasonable costs thereof are for Controller's account, unless the audit reveals a material shortcoming.

Article 11 — Liability, term and governing law

11.1 The liability regime set out in the Main Agreement and the terms and conditions (algemene voorwaarden) applies mutatis mutandis to liability under this Data Processing Agreement, including the limitations and the maximum amount contained therein.

11.2 Controller is responsible for the lawfulness of the processing, including a valid legal basis, informing data subjects and, where required, a data protection impact assessment. Fines, claims from data subjects or from the supervisory authority arising from the absence thereof or from Controller's instructions are for Controller's account. Controller indemnifies Processor against such claims.

11.3 This Data Processing Agreement applies for as long as Processor processes personal data for Controller and ends with the Main Agreement.

11.4 Dutch law applies to this Data Processing Agreement.

Annex 1 — Processing details

  • Subject matter: analysis of business processes and systems for the purpose of AI optimisation.
  • Nature and purpose:reading and aggregating data from Controller's systems in order to identify opportunities for improvement and to build/manage solutions.
  • Duration: for the term of the Main Agreement.
  • Types of personal data: names, e-mail addresses and contact details of employees/customers insofar as present in the systems analysed — expected to be limited, because data is aggregated. No special categories, unless expressly agreed.
  • Categories of data subjects: employees, customers and/or business relations of Controller.

Annex 2 — Security measures

  • Encrypted connections (TLS) and encrypted storage of access tokens.
  • Access restriction at database level (row-level security) and the principle of least privilege.
  • Exclusively read-only access to source systems, only after explicit authorisation.
  • Data minimisation: storage of aggregated results, no unnecessary raw personal data.
  • Logging and monitoring of access.
  • Back-up of data, defined retention periods and a fixed incident procedure in the event of (suspected) data breaches.

Annex 3 — Sub-processors

Sub-processorFunctionLocationTransfer safeguard
Hetzner Online GmbHServer/hostingGermany (EU)Not applicable (within EU)
SupabaseDatabase and file storageEU (eu-west-1)Not applicable (within EU)
Vercel Inc.Hosting/delivery of websiteUS (EU edge)Standard contractual clauses / Data Privacy Framework
ResendE-mail sendingUSStandard contractual clauses / Data Privacy Framework
AI model provider (e.g. Anthropic, OpenAI, EU alternative)AI processing (analysis)EU/USStandard contractual clauses; no model training; short or no log retention; client is informed in advance
Google (Cloud / Drive API)Storage of deliverables + read-only access after consentEU/USStandard contractual clauses / Data Privacy Framework